Pavel Naumov

Pavel Naumov

Global Senior Security Researcher FHP

Pavel joined Group-IB as a researcher in 2018, spent 2019 to 2021 as a developer on Digital Risk Protection, and returned to research in Fraud Protection. There he studies the technologies behind modern fraud: bots and automation, device intelligence and fingerprinting, malware. He reverse-engineers how they work and turns them into detection methods that become product capabilities.

Pavel drives the cyber-fraud fusion approach inside the company, running joint projects with the Threat Intelligence and investigation teams so that malware analysis, fraud telemetry, and case data feed a single detection picture. Pavel authors and presents Group-IB’s public fraud research.

Pavel holds a Master’s degree in Mathematical Methods of Information Security and has a background in software development and DevOps. That engineering side lets him go from hypothesis to detection himself: he designs and builds internal tooling, telemetry, and detection rules.

Blog posts by Pavel Naumov

Vwork Blog image
Fraud Protection
September 9, 2026
Vwork: Weaponized Open-source Software as an Addon for Gigabud
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.
Android SMS Stealers in Uzbekistan
Malware Analysis
December 19, 2025
Choose Your Fighter: A New Stage in the Evolution of Android SMS Stealers in Uzbekistan
Group-IB analyzes the evolution of Android malware in Uzbekistan, revealing advanced droppers, encrypted payload delivery, anti-analysis techniques, and Wonderland’s bidirectional SMS-stealing capabilities driving large-scale financial fraud.
Gold factory
Malware Analysis
December 3, 2025
Hook for Gold: Inside GoldFactory’s Сampaign That Turns Apps Into Goldmines
A deep dive into GoldFactory’s evolving mobile fraud campaigns across APAC, including modified banking apps, new malware variants such as Gigaflower, shared criminal infrastructure, and insights from the Group-IB Fraud Matrix, with recommendations for organizations and end users.
Malware Analysis
July 2, 2025
June’s Dark Gift: The Rise of Qwizzserial
Discovered by Group-IB in mid-2024, the Qwizzserial, which was initially not very active, began to spread strongly in Uzbekistan, masquerading as legitimate applications. The malware steals banking information and intercepts 2FA sms, transmitting it to fraudsters via Telegram bots.
Fraud Protection
February 20, 2025
Fingerprint Heists: How your browser fingerprint can be stolen and used by fraudsters
Discover how cybercriminals steal browser fingerprints to mimic users, bypass security measures, and commit online fraud. Learn how to protect your digital identity.
Ajina blog cover
Malware Analysis
September 12, 2024
Ajina attacks Central Asia: Story of an Uzbek Android Pandemic
Discovered by Group-IB in May 2024, the Ajina.Banker malware is a major cyber threat in the Central Asia region, disguising itself as legitimate apps to steal banking information and intercept 2FA messages.
Beware the RAT: Android Remote Access malware strikes in Malaysia
Malware Analysis
July 31, 2024
Beware CraxsRAT: Android Remote Access malware strikes in Malaysia
CraxsRAT is a notorious Android malware family known for its Remote Administration Tools (RAT), which include remote device control and advanced spyware functions like keylogging, gesture manipulation, and recording of cameras, screens, and calls.
Fraud Protection
August 14, 2023
Breaking down Gigabud banking malware with Group-IB Fraud Matrix
Uncover the disruptive nature of Gigabud malware and take proactive measures to mitigate the associated risks